Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Rahul Madduluri, Co-Founder & CTO at Doppel
In 2026, the cybersecurity threat landscape is anticipated to reach a critical inflection point, driven by the evolving use of artificial intelligence on both the offensive and defensive fronts. AI will enable the mass production of social engineering attacks. Attackers will exploit increasingly powerful generative AI models to manipulate identity, impersonate trusted relationships, and produce moments of urgency, authority, or emotional resonance.
This year’s global AI cyberattacks are projected to surpass 28 million incidents, representing a 72% year-over-year increase. Deepfake incidents, often used to impersonate executives, colleagues, or loved ones, increased 680% year-over-year, with Q1 2025 alone recording 179 separate incidents. At the same time, defenders will be forced to respond with equally adaptive systems, moving from manual detection to autonomous, real-time response. Only 7% of organizations have deployed AI-enabled defense, but 88% of companies plan to do so, as 60% of leaders believe they have already encountered an AI-enabled attack.
In this shifting environment, two trends will define how individuals and organizations protect themselves: the rise of hyper-personalized AI deception that erodes the foundations of human trust, and the emergence of AI agents that operate as the new front line of defense. Next year, we’ll see the mechanics of trust and security evolve, and how we safeguard relationships, identities, and the integrity of everyday interactions will transform just as rapidly.
The Rise of Code Words: When Every Caller Becomes a Suspect
By 2026, AI deception will blur the line between real and synthetic to the point where even personal relationships will not be safe. Scams that once relied on phishing emails are morphing into voice clones and video deepfakes that mimic a loved one’s tone, timing, and urgency. These attacks prey on fear and empathy, prompting instant reactions before logic can catch up. What was once a minor concern will become a mainstream vulnerability, affecting households, workplaces, and communities with equal force.
As these techniques grow more precise and more accessible, people will grow increasingly suspicious of incoming calls, whether known or unknown. The most cautious people will start using secret code words and subtle behavioral cues to confirm identity. This transition will transform long-standing norms of personal interaction and reshape how we assess authenticity in every moment that matters.
AI Agents as the Front Line in Cyber Defense
While individuals adjust their personal habits, organizations will confront a threat landscape that evolves faster than humans can respond. Attackers will use AI not only to scale their operations but also to increase their speed. They will launch social engineering campaigns that mutate in real time and adapt to defensive measures almost as quickly as they’re identified. In 2026, the sheer volume and velocity of social engineering attacks will outpace the combined ability of human cybersecurity analysts to take them down. Defenses that can respond to threats autonomously, using AI agents that act in real time, will be able to detect, verify, and neutralize campaigns in seconds while continuously learning from every takedown. These systems will operate with an efficiency that mirrors that of the attackers themselves, noting patterns, updating risk models, and executing defense strategies.
Even as automation becomes more widespread, human analysts will remain essential. Their ability to close the loop by identifying gaps in the graph and in AI will make defenses smarter and more adaptive. Human expertise will continue to shape the logic and boundaries of autonomous action, ensuring that machine-speed response is grounded in the most relevant strategic threat intel.
New Rituals For a More Resilient Future
By 2026, the convergence of AI-powered deception and AI-driven defense will require a fundamental reset in how we think about trust.
As AI-generated voices, images, and personas become indistinguishable from the real thing, individuals will turn to new communication norms to preserve authenticity, even in their closest relationships. For organizations, the same pressure will push cybersecurity into an era of autonomous protection. AI agents capable of detecting, validating, and disrupting threats in seconds will become essential, working alongside human analysts to stay ahead of rapidly advancing attacks.
These trends signal a future in which trust is engineered, identity is validated, and defense is enacted at machine speed. In this landscape, it’s imperative to embrace these shifts early, practicing better judgment and working with advanced technology to help cultivate a more resilient and secure world.
##
ABOUT THE AUTHOR
Rahul Madduluri is the co-founder and CTO of Doppel, where he leads product, engineering, IT and security. Rahul started his career as a software engineer at Uber, using machine learning to predict arrival time estimates. He later started a company that aggregates Shopify stores and joined South Park Commons as a Founder Fellow. Rahul holds a Bachelor of Science (BS) degree in Computer Science & Computer Engineering from the University of Southern California.





